CWE-400
3,613 CVEs • Abstraction: Class • Likelihood of Exploit: High
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CVEs (3,613)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian FedoraprojectLinuxfoundation3Containerd Debian LinuxFedoraJun 17, 2026 Jun 9, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 containerd is an open source container runtime. A bug was found in the containerd's CRI implementation where programs inside a container can cause the containerd daemon to consume memory without bound during invocation o...Show more |
3Fedoraproject KubernetesRedhat4Cri O Enterprise LinuxFedora+1 moreJun 17, 2026 Jun 7, 2022 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 A vulnerability was found in CRI-O that causes memory or disk space exhaustion on the node for anyone with access to the Kube API. The ExecSync request runs commands in a container and logs the output of the command. Thi...Show more |
MinIO is a multi-cloud object storage solution. Starting with version RELEASE.2019-09-25T18-25-51Z and ending with version RELEASE.2022-06-02T02-11-04Z, MinIO is vulnerable to an unending go-routine buildup while keeping...Show more |
Dell PowerStore contains an Uncontrolled Resource Consumption Vulnerability in PowerStore User Interface. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the Denial of Service. |
1Mattermost 1Mattermost Server Jun 17, 2026 Jun 2, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Uncontrolled resource consumption in Mattermost version 6.6.0 and earlier allows an authenticated attacker to crash the server via a crafted SVG attachment on a post. |
Play Framework is a web framework for Java and Scala. A denial of service vulnerability has been discovered in verions 2.8.3 through 2.8.15 of Play's forms library, in both the Scala and Java APIs. This can occur when us...Show more |
4Debian HaxxNetapp+1 more12Clustered Data Ontap CurlDebian Linux+9 moreJun 17, 2026 Jun 2, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 libcurl provides the `CURLOPT_CERTINFO` option to allow applications torequest details to be returned about a server's certificate chain.Due to an erroneous function, a malicious server could make libcurl built withNSS g...Show more |
1Rockwellautomation 9Compact Guardlogix 5370 Firmware Compact Guardlogix 5380 FirmwareCompactlogix 5370 Firmware+6 moreJun 17, 2026 Jun 2, 2022 N/A· v4 8.6 HIGH· v3 7.8 HIGH· v2 A malformed Class 3 common industrial protocol message with a cached connection can cause a denial-of-service condition in Rockwell Automation Logix Controllers, resulting in a major nonrecoverable fault. If the target d...Show more |
1Nextcloud 1Nextcloud Server Jun 17, 2026 May 31, 2022 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Prior to versions 22.2.7 and 23.0.4, missing input-size validation of new session names allows users to create app password...Show more |
2Netapp Redhat8Active Iq Unified Manager IntegrationJboss Enterprise Application Platform+5 moreJun 17, 2026 May 24, 2022 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in Undertow. A potential security issue in flow control handling by the browser over http/2 may potentially cause overhead or a denial of service in the server. The highest threat from this vulnerability...Show more |
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.ragged.constant` does not fully validate the input arguments. This results in a deni...Show more |
Go Ethereum is the official Golang implementation of the Ethereum protocol. Prior to version 1.10.17, a vulnerable node, if configured to use high verbosity logging, can be made to crash when handling specially crafted p...Show more |
1Siemens 2Simatic Cp 442 1 Rna Firmware Simatic Cp 443 1 Rna FirmwareJun 17, 2026 May 20, 2022 N/A· v4 6.5 MEDIUM· v3 6.1 MEDIUM· v2 A vulnerability has been identified in SIMATIC CP 442-1 RNA (All versions < V1.5.18), SIMATIC CP 443-1 RNA (All versions < V1.5.18). The affected devices improperly handles excessive ARP broadcast requests. This could al...Show more |
OPC UA Legacy Java Stack 2022-04-01 allows a remote attacker to cause a server to stop processing messages by sending crafted messages that exhaust available resources. |
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (nvidia.ko), where uncontrolled resource consumption can be triggered by an unprivileged regular user, which may lead to denial of service. |
1Intel 1Software Guard Extensions Jun 17, 2026 May 12, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Uncontrolled resource consumption in the Linux kernel drivers for Intel(R) SGX may allow an authenticated user to potentially enable denial of service via local access. |
Uncontrolled Resource Consumption in GitHub repository causefx/organizr prior to 2.1.2000. This vulnerability can be abused by doing a DDoS attack for which genuine users will not able to access resources/applications. |
3Apache DebianOracle3Debian Linux Hospitality Cruise Shipboard Property Management SystemTomcatJun 17, 2026 May 12, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted...Show more |
2Fedoraproject Microsoft5.net .net CoreFedora+2 moreJun 17, 2026 May 10, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 .NET and Visual Studio Denial of Service Vulnerability |
2Fedoraproject Microsoft5.net .net CoreFedora+2 moreJun 17, 2026 May 10, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 .NET and Visual Studio Denial of Service Vulnerability |